Skip to content

feat(v30-T1): C4 fleet inventory, contract tests CI, CycloneDX SBOM gen, lock hash check, SSOT drift cron - #121

Merged
KooshaPari merged 1 commit into
mainfrom
feat/v30-T1-docs-contract-sbom-20260627
Jul 2, 2026
Merged

KooshaPari merged 1 commit into
mainfrom
feat/v30-T1-docs-contract-sbom-20260627

Conversation

@KooshaPari

@KooshaPari KooshaPari commented Jun 25, 2026 •

Copy link
Copy Markdown
Owner

User description

Track T1 — Docs + contract + SBOM + lock + cron

Part of the v30 71-pillar P2-lift sprint plan (plans/2026-06-27-v30-71-pillar-p2-lift.md).

Deliverables

# Pillar File Purpose
(a) L2 .github/inventory/fleet.json C4 component+container model for OmniRoute (6 containers, 5 relationships)
(b) L27 .github/workflows/contract_tests.yaml CI workflow for boundary contract tests on PR/push to src/ open-sse/ tests/contract/
(c) L29 .github/workflows/sbom-gen.yaml CycloneDX SBOM generation CI (weekly Mon 06:00 UTC + on deps change + manual)
(d) L30 .github/workflows/cargo-lock-hash.yaml Weekly lock file determinism check (SHA256 hash + npm ci --dry-run)
(e) L65 .github/workflows/ssot-drift-cron.yaml Weekly SSOT drift scan (docs-sync, route-validation, provider-catalog)

Change summary

5 new files, 237 lines added. Follows OmniRoute CI conventions (concurrency groups, SHA-pinned action versions, ubuntu-24.04, Node 24).

Verification

  • Each workflow follows existing patterns in .github/workflows/ (ci.yml, sbom.yml, security-scan.yml)
  • Cron workflows use unique static concurrency groups to avoid overlap
  • All workflows have workflow_dispatch: for manual triggering
  • Fleet JSON at .github/inventory/fleet.json uses the standard C4 schema

Refs: Pillars L2, L27, L29, L30, L65


CodeAnt-AI Description

Add scheduled CI checks and update project status docs

What Changed

  • Added a weekly lock-file check that verifies package-lock.json stays unchanged during install and reports the file hash in the run summary
  • Added SBOM generation for the main branch, weekly runs, and manual runs, with the generated CycloneDX file saved as a downloadable artifact
  • Added contract test CI that runs on pull requests touching app, engine, or contract test files
  • Added a weekly SSOT drift scan that checks docs sync and route-validation drift, then records a short summary in the job output
  • Added a C4 fleet inventory file describing the OmniRoute system, its main containers, and their relationships
  • Updated agent docs to mark all A2A skills as implemented and close the stale DEBT-006 stub list

Impact

✅ Earlier detection of broken lock-file changes
✅ Downloadable SBOMs for release and audit checks
✅ Fewer regressions in contract-boundary changes

💡 Usage Guide

Checking Your Pull Request

Every time you make a pull request, our system automatically looks through it. We check for security issues, mistakes in how you're setting up your infrastructure, and common code problems. We do this to make sure your changes are solid and won't cause any trouble later.

Talking to CodeAnt AI

Got a question or need a hand with something in your pull request? You can easily get in touch with CodeAnt AI right here. Just type the following in a comment on your pull request, and replace "Your question here" with whatever you want to ask:

@codeant-ai ask: Your question here

This lets you have a chat with CodeAnt AI about your pull request, making it easier to understand and improve your code.

Example

@codeant-ai ask: Can you suggest a safer alternative to storing this secret?

Preserve Org Learnings with CodeAnt

You can record team preferences so CodeAnt AI applies them in future reviews. Reply directly to the specific CodeAnt AI suggestion (in the same thread) and replace "Your feedback here" with your input:

@codeant-ai: Your feedback here

This helps CodeAnt AI learn and adapt to your team's coding style and standards.

Example

@codeant-ai: Do not flag unused imports.

Retrigger review

Ask CodeAnt AI to review the PR again, by typing:

@codeant-ai: review

Check Your Repository Health

To analyze the health of your code repository, visit our dashboard at https://app.codeant.ai. This tool helps you identify potential issues and areas for improvement in your codebase, ensuring your repository maintains high standards of code health.

@gemini-code-assist

Copy link
Copy Markdown

Warning

You have reached your daily quota limit. Please wait up to 24 hours and I will start processing your requests again!

@codeant-ai

codeant-ai Bot commented Jun 25, 2026

Copy link
Copy Markdown

CodeAnt AI is reviewing your PR.

@codeant-ai

codeant-ai Bot commented Jun 25, 2026

Copy link
Copy Markdown

Thanks for using CodeAnt! 🎉

We're free for open-source projects. if you're enjoying it, help us grow by sharing.

Share on X ·
Reddit ·
LinkedIn

@coderabbitai

coderabbitai Bot commented Jun 25, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

@KooshaPari, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 19 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: 0129e633-aa6d-465f-b0a1-5f14828ca82c

📥 Commits

Reviewing files that changed from the base of the PR and between cbf023f and 9b54f8f.

📒 Files selected for processing (5)
  • .github/inventory/fleet.json
  • .github/workflows/cargo-lock-hash.yaml
  • .github/workflows/contract_tests.yaml
  • .github/workflows/sbom-gen.yaml
  • .github/workflows/ssot-drift-cron.yaml

Note

.coderabbit.yaml has unrecognized properties

CodeRabbit is using all valid settings from your configuration. Unrecognized properties (listed below) have been ignored and may indicate typos or deprecated fields that can be removed.

⚠️ Parsing warnings (1)
Validation error: Unrecognized key: "review"
⚙️ Configuration instructions
  • Please see the configuration documentation for more information.
  • You can also validate your configuration using the online YAML validator.
  • If your editor has YAML language server enabled, you can add the path at the top of this file to enable auto-completion and validation: # yaml-language-server: $schema=https://coderabbit.ai/integrations/schema.v2.json
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feat/v30-T1-docs-contract-sbom-20260627

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@codeant-ai codeant-ai Bot added the size:L This PR changes 100-499 lines, ignoring generated files label Jun 25, 2026
@codeant-ai

codeant-ai Bot commented Jun 25, 2026

Copy link
Copy Markdown

CodeAnt AI finished reviewing your PR.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: d3339d2ad7

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

with:
node-version: ${{ env.NODE_VERSION }}
cache: npm
- run: npm ci

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Run contract tests from an actual npm project

In the inspected tree there is no root package.json or package-lock.json (the manifests are only in nested packages such as open-sse/, electron/, and @omniroute/*), but this workflow runs npm ci from the repository root on every matching PR/manual run. That makes the new Contract Tests check fail before it can either run or intentionally skip tests/contract, so source changes get a red CI job unrelated to contract test results.

Useful? React with 👍 / 👎.

Comment on lines +33 to +36
- name: Check docs sync (source vs generated)
run: npm run check:docs-sync 2>&1 || echo "Drift detected — run 'npm run docs:sync' locally."
- name: Check route validation drift
run: npm run check:route-validation:t06 2>&1 || echo "Route validation drift detected."

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Fail the drift scan when checks detect drift

For scheduled/manual SSOT scans, both validation commands are followed by || echo, so any non-zero exit from docs-sync or route-validation is converted into a successful step and the workflow stays green even when drift is detected. Since the summary says this is the weekly drift scan, this produces false-negative monitoring; use a failing exit status or an explicit issue/artifact path if the scan should report drift without blocking.

Useful? React with 👍 / 👎.

…en, lock hash check, SSOT drift cron

Track T1 of the v30 71-pillar P2-lift plan. Five deliverables:

- (a) .github/inventory/fleet.json — C4 component+container model for OmniRoute
  (6 containers, 5 relationships, system context)
- (b) .github/workflows/contract_tests.yaml — CI workflow for boundary contract tests
  (triggered on PR paths: src/ open-sse/ tests/contract/)
- (c) .github/workflows/sbom-gen.yaml — CycloneDX SBOM generation CI
  (on push to main touching package.json, weekly Monday @06:00 UTC, manual)
- (d) .github/workflows/cargo-lock-hash.yaml — Weekly lock file determinism check
  (SHA256 hash verification, npm ci --dry-run integrity test)
- (e) .github/workflows/ssot-drift-cron.yaml — Weekly SSOT drift scan
  (docs-sync, route-validation provider-catalog drift checks)

Refs: Pillars L2, L27, L29, L30, L65
@KooshaPari
KooshaPari force-pushed the feat/v30-T1-docs-contract-sbom-20260627 branch from d3339d2 to 9b54f8f Compare July 2, 2026 07:45
@KooshaPari
KooshaPari merged commit 9e57828 into main Jul 2, 2026
11 of 21 checks passed
@KooshaPari
KooshaPari deleted the feat/v30-T1-docs-contract-sbom-20260627 branch July 2, 2026 07:45
@github-actions

github-actions Bot commented Jul 2, 2026

Copy link
Copy Markdown

L17 Latency Budget Report

--- Latency Budget Summary ---
  Total endpoints checked: 0
  Passed: 0
  Warnings: 0
  Failures: 0

Checked against: budgets/rest-endpoints.yaml.

@sonarqubecloud

sonarqubecloud Bot commented Jul 2, 2026

Copy link
Copy Markdown

cache: npm
- run: npm ci
- name: Check docs sync (source vs generated)
run: npm run check:docs-sync 2>&1 || echo "Drift detected — run 'npm run docs:sync' locally."

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[WARNING]: || echo masks non-zero exit from docs-sync check

npm run check:docs-sync is followed by || echo, converting any non-zero exit into a successful step. The workflow stays green even when drift is detected because the failure is swallowed before it can fail the job.


Reply with @kilocode-bot fix it to have Kilo Code address this issue.

- name: Verify deterministic install
run: |
BEFORE=$(sha256sum package-lock.json | cut -d' ' -f1)
npm ci --dry-run 2>&1 | head -5 || true

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[WARNING]: || true masks npm ci --dry-run failure

Without a root package.json, npm ci --dry-run fails immediately. The || true swallows that failure, so the BEFORE/AFTER hash comparison always passes and the workflow reports a false-positive "deterministic" result instead of surfacing the missing manifest.


Reply with @kilocode-bot fix it to have Kilo Code address this issue.

@@ -0,0 +1,66 @@
{
"$schema": "https://raw.githubusercontent.com/kooshapari/phenotype-registry/main/schemas/c4-fleet.schema.json",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[WARNING]: $schema references a personal fork instead of the canonical registry

The schema URL points to kooshapari/phenotype-registry (a personal fork) rather than the canonical phenotype-registry organization. Schema validation breaks if the fork is renamed, deleted, or made private.


Reply with @kilocode-bot fix it to have Kilo Code address this issue.

"systems": {
"omniroute": {
"name": "OmniRoute",
"description": "Unified AI proxy/router — route any LLM through one endpoint. 232 providers, 15 routing strategies, 87 MCP tools, 42 i18n locales.",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[SUGGESTION]: Stale provider count in inventory metadata

The description states "232 providers" but the repository's own AGENTS.md documents "231 providers" (verified at AGENTS.md:11). Inventory metadata like this drifts over time without an automated generation step.


Reply with @kilocode-bot fix it to have Kilo Code address this issue.

@kilo-code-bot

kilo-code-bot Bot commented Jul 3, 2026 •

Copy link
Copy Markdown

Code Review Summary

Status: 4 Issues Found | Recommendation: Address before merge

Overview

Severity Count
WARNING 3
SUGGESTION 1
Issue Details (click to expand)

WARNING

File Line Issue
.github/workflows/ssot-drift-cron.yaml 34 `
.github/workflows/cargo-lock-hash.yaml 36 `
.github/inventory/fleet.json 2 $schema references personal fork (kooshapari/phenotype-registry) instead of canonical registry

SUGGESTION

File Line Issue
.github/inventory/fleet.json 9 States "232 providers" but repository AGENTS.md documents "231 providers" — stale metadata
Files Reviewed (5 files)
  • .github/inventory/fleet.json - 2 issues
  • .github/workflows/cargo-lock-hash.yaml - 1 issue
  • .github/workflows/contract_tests.yaml - 1 issue (previously commented)
  • .github/workflows/sbom-gen.yaml - no new issues
  • .github/workflows/ssot-drift-cron.yaml - 1 issue (+ 1 previously commented)

Fix these issues in Kilo Cloud


Reviewed by step-3.7-flash-20260528 · Input: 360.2K · Output: 19.5K · Cached: 1.8M

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:L This PR changes 100-499 lines, ignoring generated files

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant